You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(verify): publish a TDX capture that binds a TRACE record's signing key (#69)
The July GCP captures bind a manifest hash whose input was never published,
so /verify and the homepage could only say genuine silicon. A capture taken
on 2026-09-14 in a new C3 trust domain puts SHA-256 of an Ed25519 key,
generated inside the TD, in REPORTDATA and signs a TRACE v0.3 record with it.
The quote, the record and the capture program are published under
verify/fixtures. verify/key-binding.js checks the binding in the browser and
the homepage panel; tools/check-key-binding.py checks the record signature,
binding, quote, MRTD and program digest with the Python SDK in the verifier
job. The differential now covers three captures, 5,526 inputs.
verify/fixtures is marked -text, since every file there is pinned by hash.
Claude-Session: https://claude.ai/code/session_013aK3gVWzNdcM3hZ2o2awK2
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
<lidata-step="quote-signature"><spanclass="key">step 1</span><span>attestation key signature over header and TD report</span><spanclass="state">not run</span></li>
182
182
<lidata-step="qe-binding"><spanclass="key">step 2</span><span>QE report binds the attestation key</span><spanclass="state">not run</span></li>
183
183
<lidata-step="qe-report-signature"><spanclass="key">step 3</span><span>QE report signed by the platform PCK certificate</span><spanclass="state">not run</span></li>
184
184
<lidata-step="pck-chain"><spanclass="key">step 4</span><span>PCK chain ends at the pinned Intel SGX Root CA</span><spanclass="state">not run</span></li>
185
-
<lidata-step="reportdata"><spanclass="key">REPORTDATA</span><span>32 bytes set by the guest</span><spanclass="state note">see note</span></li>
185
+
<lidata-step="reportdata"><spanclass="key">REPORTDATA</span><span>commits to the key that signed a published TRACE record</span><spanclass="state">not run</span></li>
186
186
<lidata-step="verdict"><spanclass="key">verdict</span><span>genuine Intel TDX silicon signed this quote</span><spanclass="state">not run</span></li>
187
187
</ol>
188
188
</figure>
189
189
<divclass="verify-foot">
190
-
<p><spanclass="tag">Note</span>This quote proves genuine Intel TDX silicon signed it. Its REPORTDATA holds a manifest hash whose input was not published, so itdoes not yet tie a specific record to this machine.</p>
190
+
<p><spanclass="tag">Note</span>Genuine Intel TDX silicon signed this quote, and its REPORTDATA commits to the key that signed the TRACE record published beside it. It does not show that the software inside the trust domain was the image anyone intended.</p>
191
191
<p>Runs in your browser. Nothing is sent back to us.</p>
192
192
</div>
193
193
</div>
@@ -271,7 +271,7 @@ <h3>AMD SEV-SNP</h3>
271
271
<articleclass="ecosystem-card">
272
272
<h3>Intel TDX</h3>
273
273
<p>GCP C3. Quotes verify offline to the pinned Intel SGX Root CA, no collateral service needed.</p>
274
-
<aclass="evidence-link" href="/verify/">Check the 2026-07-21 capture yourself →</a>
274
+
<aclass="evidence-link" href="/verify/">Check the 2026-09-14 capture yourself →</a>
Copy file name to clipboardExpand all lines: llms.txt
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ AgenTrust is the ecosystem at https://agentrust-io.com and the GitHub organizati
7
7
## Start here
8
8
9
9
- [Overview](https://agentrust-io.com/): The verifiable AI supply chain from model weights to agent actions, the hardware it is validated on, and what the evidence does and does not prove.
10
-
- [Verify an Intel TDX quote](https://agentrust-io.com/verify/): Runs the four-step DCAP check on a genuine GCP confidential VM quote in the browser, ending at the pinned Intel SGX Root CA. A pass proves genuine Intel TDX silicon signed the quote. These captures do not tie a TRACE record to that machine, and the check does not appraise TCB currency or revocation.
10
+
- [Verify an Intel TDX quote](https://agentrust-io.com/verify/): Runs the four-step DCAP check on a genuine GCP confidential VM quote in the browser, ending at the pinned Intel SGX Root CA, then checks that the quote's REPORTDATA commits to the signing key of a TRACE record published beside it. A pass proves genuine Intel TDX silicon signed the quote and bound that key. The check does not appraise TCB currency or revocation, or show that the measured image is the one anyone intended.
11
11
- [10-minute tool-call tutorial](https://agentrust-io.com/quickstart/): Write a policy, observe a denied call, and inspect a signed session record on a laptop. Software mode provides no hardware isolation or hardware-backed provenance.
12
12
- [Weight Custody Manifest (WCM)](https://wcm.agentrust-io.com/): Bind model-weight identity and custody terms to key-release policy. The local walkthrough uses synthetic evidence and a placeholder key; it does not load a real model or demonstrate hardware protection.
13
13
- [Runnable demos](https://agentrust-io.com/demos/): Software examples for policy decisions, evidence verification, delegation, and model-weight custody. Follow each demo's stated prerequisites and limits.
console.log('PASS both GCP TDX captures verify; tampered quote and expired chain are rejected at the right step');
116
+
console.log('PASS all three GCP TDX captures verify, the key-binding capture commits to its record key; tampered quote and expired chain are rejected at the right step');
0 commit comments